CVE-2012-6274
UnknownEPSS 46.87%
Last modified
CVE-2012-6274 is a vulnerability of currently unknown severity. BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors.. EPSS estimates a 46.87% chance of exploitation in the next 30 days.
Description
BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bigantsoft | Bigant Im Message Server | All versions |
References
- http://www.kb.cert.org/vuls/id/990652US Government Resource
- http://www.kb.cert.org/vuls/id/990652US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-6274?
BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors.
How severe is CVE-2012-6274?
Severity scoring for CVE-2012-6274 is pending analysis. The EPSS model estimates a 46.87% probability of exploitation in the next 30 days.
How do I fix CVE-2012-6274?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2012
- CVE-2012-6268Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2012-6269Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2012-6270Adobe Shockwave Player through 11.6.8.638 allows remote atta…
- CVE-2012-6271Adobe Shockwave Player through 11.6.8.638 allows remote atta…
- CVE-2012-6272Multiple cross-site scripting (XSS) vulnerabilities in Dell …
- CVE-2012-6273SQL injection vulnerability in BigAntSoft BigAnt IM Message …
- CVE-2012-6275Multiple stack-based buffer overflows in AntDS.exe in BigAnt…
- CVE-2012-6276Directory traversal vulnerability in the web-based managemen…
- CVE-2012-6277Multiple unspecified vulnerabilities in Autonomy KeyView IDO…7.8
- CVE-2012-6278Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2012-6279Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2012-6280Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2012-6274?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
